Logfile of HijackThis v1.99.1 Scan saved at 07:36:38 ., on 2007/02/26 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\ZONELABS\vsmon.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Freeshare\Screen Capture Utility\ScreenCaptureUtility.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\WINDOWS\system32\ZoneLabs\isafe.exe C:\WINDOWS\System32\svchost.exe C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe C:\Documents and Settings\Alireza\Desktop\HijackThis.exe O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: Site Unavailable O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
Sorry, this GeoCities site is currently unavailable.
O1 - Hosts:

The GeoCities web site you were trying to view has temporarily exceeded its data transfer limit. Please try again later.

O1 - Hosts:

Are you the site owner? O1 - Hosts: Avoid service interruptions in the future by increasing your data transfer limit! O1 - Hosts: Find out how.

O1 - Hosts:

Learn more about data transfer.

O1 - Hosts:
O1 - Hosts:
O1 - Hosts: Yahoo! GeoCities O1 - Hosts:
SPONSORED LINKS
O1 - Hosts: O1 - Hosts:
O1 - Hosts: O1 - Hosts:
Reliable plans include domain & 24x7 support.
O1 - Hosts: O1 - Hosts:
O1 - Hosts:
O1 - Hosts: O1 - Hosts:
Includes starter web page, email & domain forwarding, 24x7 support.
O1 - Hosts: O1 - Hosts:
O1 - Hosts:
O1 - Hosts: O1 - Hosts:
Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning.
O1 - Hosts: O1 - Hosts:
O1 - Hosts:
O1 - Hosts: O1 - Hosts:
$50 setup fee waived. A reliable ecommerce plan, 24x7 support.
O1 - Hosts: O1 - Hosts:
O1 - Hosts:
O1 - Hosts: Get your own web site at
Yahoo! GeoCities O1 - Hosts: Hosted by Yahoo! Web Hosting O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts: Copyright © O1 - Hosts: 2005 Yahoo! Inc. All rights reserved
O1 - Hosts: Privacy Policy O1 - Hosts: - Copyright Policy O1 - Hosts: - Guidelines O1 - Hosts: - Terms of Service O1 - Hosts: - Help O1 - Hosts:
O1 - Hosts:
O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: 1 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [FreeShare Screen Capture Tool] C:\Program Files\Freeshare\Screen Capture Utility\ScreenCaptureUtility.exe O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKLM\..\Run: [QSmile] C:\Program Files\AsefSoft\Quick Smile 3\QSmile.exe /h O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet O8 - Extra context menu item: Download using LeechGet - file://C:\Program Files\LeechGet 2006\\AddUrl.html O8 - Extra context menu item: Download using LeechGet Wizard - file://C:\Program Files\LeechGet 2006\\Wizard.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Parse with LeechGet - file://C:\Program Files\LeechGet 2006\\Parser.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{BEBB2F2B-4C56-4D11-A852-66BA3972F73E}: NameServer = 192.9.9.3 O17 - HKLM\System\CCS\Services\Tcpip\..\{D023524B-09BA-4242-89EE-1BBB8AD6AF71}: NameServer = 85.15.1.10 85.185.53.5 O20 - Winlogon Notify: NavLogon - C:\WINDOWS\ O20 - Winlogon Notify: winqeo32 - winqeo32.dll (file missing) O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing) O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-nt.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe